# Title: Vox TG790 ADSL Router - Cross-Site Request Forgery (Add Admin) # Author: Cakes # Exploit Date: 2018-08-01 # Vendor: Vox Telecom # Link: https://www.vox.co.za/ # Firmware Version: 6.2.W.1 # CVE: N/A # Description # Due to improper session management low privilege users are able to create # administrator accounts through a crafted POST request. # PoC